WordPress.org

Security Scorecard

Score

33D

Total CVEs

870

Patch Rate

46%

396 patched

Avg Response

104d

days to patch

Critical Gaps

8

exploitable, no detection

Severity Breakdown

Critical39
High149
Medium680
Low2

Patch Status

Patched396 (46%)
Partial/Workaround4 (0%)
Unpatched470 (54%)

CVEs (1,095)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-14610TableMaster for Elementor Plugin VulnerabilityHigh7.2-Patched
CVE-2025-8072Target Video Easy Publish Plugin VulnerabilityMedium6.4-Patched
CVE-2026-1083WordPress Booking Calendar Plugin VulnerabilityMedium4.4-Patched
CVE-2026-0702VidShop Shoppable Videos VulnerabilityHigh7.5-Patched
CVE-2025-14795WordPress Plugin XSSMedium4.3-Patched
CVE-2025-14971WooCommerce Invoice Payment Plugin VulnerabilityMedium5.3-Patched
CVE-2025-6461CubeWP VulnerabilityMedium4.3-Patched
CVE-2025-12836VK Google Job Posting Manager Plugin XSSMedium6.4-Patched
CVE-2025-13374Kalrav AI Agent Plugin XSSCritical9.8-Patched
CVE-2025-13676WordPress Plugin XSSMedium6.1-Patched